US11811924B1ActiveUtility

System and method of securing a server using elliptic curve cryptography

Assignee: SAFEMOON US LLCPriority: Nov 23, 2022Filed: Feb 10, 2023Granted: Nov 7, 2023
Est. expiryNov 23, 2042(~16.3 yrs left)· nominal 20-yr term from priority
H04L 9/0869H04L 9/0631H04L 9/0825H04L 9/3066H04L 9/0894H04L 9/0662
83
PatentIndex Score
1
Cited by
13
References
9
Claims

Abstract

A system for generating a symmetric key to allow the sharing of information between two entities, wherein the shared information is used to start a server and the symmetric key is established from the private key of a first client and the public key of a second client and for use in a symmetric encryption methodology to encrypt information for transport to the second entity, allowing the second entity to form the same symmetric key to decrypt information with no key transport required.

Claims

exact text as granted — not AI-modified
We claim: 
     
       1. A system comprising the following components:
 a client device with a processor, an input device, a memory containing a client device application and optional external storage device; 
 a crypto package containing at least each of an Advanced Encryption Standard (AES, Secure Hash Algorithm 256-bit (Sha256), Pseudorandom Number Generator (PRNG) and elliptic curve function on both the server and the client; and 
 a server with a processor and a memory containing one or more databases, such database(s) containing encrypted secret data and the crypto package; 
 generating, via the processor of the server, a symmetric key to decrypt data stored on a server and perform work on the server; 
 such system components executing the following steps (lower case letters are in reference to  FIG.  2   ): 
 1. Provisioning the system, which provisioning includes the following sub steps:
 a. Inputting, via the processor of the client device, a first set of credentials, such first set of credentials embodied as a username and password into the client device application; 
 b. Generating, via the processor of the client device, phantom credentials embodied as a phantom username and phantom password, wherein the phantom credentials are pseudo random regenerative credentials using the first set of credentials as seed to the PRNG; 
 c. Generating, via the processor of the client device, a first symmetric encryption key, such first symmetric encryption key embodied as a random string from the phantom credentials, such that the first symmetric encryption key is regenerative, using the phantom credentials to seed the PRNG process; 
 d. Inputting, via the input device of the client device, a personal identification number (PIN); 
 e. Encrypting, via the processor of the client device, the phantom credentials using the PIN to create a second symmetric encryption key; 
 f. Storing, via the processor of the client device, the encrypted phantom credentials on the client external storage device; 
 g. Inputting, via the input device of the client device, user secret data; 
 h. Initiating, via the processor of the client device, the AES engine to use the first symmetric encryption key to encrypt the secret data from the client device and send the encrypted secret data to the server memory; 
 i. Storing, via the processor of the server, the encrypted secret data on the server database; 
 
 2. Utilizing the system, which utilizing includes the following sub steps:
 j. Inputting, via the input device of the client device, the PIN; 
 k. Retrieving, via the processor of the client device, the encrypted phantom credentials from the client external storage device into the client device processor; 
 l. Decrypting, via the processor of the client device, the phantom credentials using the PIN to create the second symmetric decryption key; 
 m. Generating, via the processor of the client device, the first symmetric encryption key from the phantom credentials; 
 n. Sending, via the processor of the client device, a request from the client device to the server processor for an elliptic public key; 
 o. Generating, via the processor of the client device, a fake client elliptic private key embodied as a random string; 
 p. Generating, via the processor of the client device, a fake client elliptic public key from the fake client elliptic private key; 
 q. Sending, via the processor of the server, a server temporary elliptic public key from the server processor to the client device processor; 
 r. Generating, via the processor of the client device, a third symmetrical encryption key via the client device from the fake client elliptic private key and server temporary elliptic public key; 
 s. Encrypting, via the processor of the client device, the first symmetric encryption key using the third symmetric encryption key and sending the encrypted first symmetric encryption key and the fake client elliptic public key from the client device processor to the server memory; 
 t. Extracting, via the processor of the server, the encrypted secret data from the server database and sending the encrypted first symmetric encryption key and the fake client elliptic public key from the client device memory to the server memory; 
 u. Generating, via the processor of the server, a fourth symmetric encryption key using the server temporary elliptic private key and the fake client elliptic public key; 
 v. Decrypting, via the processor of the server, the encrypted first symmetric encryption key using the fourth symmetric encryption key as a decryption key and thereby recovering the first symmetric encryption key; 
 w. Decrypting, via the processor of the server, the encrypted secret data stored on the server database using the first symmetric encryption key as an AES decryption key and thereby recovering the previously input secret data; and 
 x. Performing, via the processor of the server, work using the decrypted secret data. 
 
 
     
     
       2. The system of  claim 1 , wherein the external storage device is taken from a group consisting of a USB drive or similar memory dongle, smart card, near field communication (NFC) device, an Internet of Things (IoT) device or an external trusted cloud database. 
     
     
       3. The system of  claim 1 , wherein the phantom username and phantom password of Step 1b are pseudo random strings formed from the username and password and cannot be reversed to retrieve the original credentials. 
     
     
       4. The system of  claim 1 , wherein the credentials stored on the external device in Step 2l are protected with a PIN, which PIN may be used as an encryption key to encrypt the credentials. 
     
     
       5. The system of  claim 1 , wherein the first symmetric encryption key is a 32 byte pseudo random string generated from the first set of credentials. 
     
     
       6. The system of  claim 1 , wherein client specific encrypted secret data is stored on the server and such encrypted secret data information can only be accessed with the permission of the client. 
     
     
       7. The system of  claim 1 , wherein the client transfers a key to the server to access the data and perform the work associated with the decrypted secret data. 
     
     
       8. The system  claim 1 , wherein the PIN and external storage device are given to a trusted Notary to authorize the server to perform work. 
     
     
       9. The system of  claim 1 , wherein the third and fourth symmetric encryption keys are formed from the product of an integer and an elliptic curve point.

Join the waitlist — get patent alerts

Track US11811924B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.